yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-6429
Component Overview
Vulnerability Overview
Name
CVE-2026-6429
Source
NVD (
link
)
Debian (
link
)
Description
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
CWEs
Published Date
May 13, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://curl.se/docs/CVE-2026-6429.html
Patch
https://curl.se/docs/CVE-2026-6429.json
Product
https://hackerone.com/reports/3677759
Exploit
Analysis
#
Affected Component
Analysis
curl
Exploitable
Vulnerability Ratings
#
5.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libcurl
buildroot
2025.02.x
8.20.0
Not Affected
libcurl
buildroot
master
8.21.0
Not Affected
curl
openwrt
master
8.19.0-r2
Exploitable
libcurl-gnutls
openwrt
master
8.20.0-r1
Not Affected
curl
openwrt
openwrt-25.12
8.19.0-r2
Exploitable
libcurl-gnutls
openwrt
openwrt-25.12
8.14.1-r1
Exploitable
curl
yocto
kirkstone
7.82.0
Exploitable
curl
yocto
master
8.20.0
Not Affected